[CLSA-2025:1760705964] Fix of 5 CVEs
Type:
security
Severity:
Moderate
Release date:
2025-10-17 13:21:00 UTC
Description:
* SECURITY UPDATE: Web cache poisoning vulnerability - debian/patches/CVE-2021-23336.patch: fix web cache poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs - CVE-2021-23336 * SECURITY UPDATE: Regular expression denial of service - debian/patches/CVE-2021-3733.patch: fix flaw in urllib’s AbstractBasicAuthHandler that could lead to a denial of service by leveraging a regular expression - CVE-2021-3733 * SECURITY UPDATE: Constant-time-defeating optimisations issue - debian/patches/CVE-2022-48566.patch: make compare_digest more constant-time - CVE-2022-48566 * SECURITY UPDATE: Incorrect parsing of email addresses containing special characters - debian/patches/CVE-2023-27043.patch: Fix email address parsing errors by adding optional 'strict' parameter to getaddresses() and parseaddr() functions - CVE-2023-27043 * SECURITY UPDATE: TLS handshake bypass - debian/patches/CVE-2023-40217.patch: Check for & avoid the ssl pre-close flaw. Update SSL tests - CVE-2023-40217
Updated packages:
  • alt-python27_2.7.18-8_amd64.deb
    sha:89622ac2eb9dabbf5a0518f746f47f863d760a66
  • alt-python27-debug_2.7.18-8_amd64.deb
    sha:8cf4f3582ad9978733dc63e43652f548e79c16e6
  • alt-python27-devel_2.7.18-8_amd64.deb
    sha:d54064f3c4ed1403e5a83e2f0c64d5ae7f83586f
  • alt-python27-idle_2.7.18-8_amd64.deb
    sha:0d8a0d16ea6464e99160776c2f827424b21e61a9
  • alt-python27-libs_2.7.18-8_amd64.deb
    sha:a5c8d82d03833830e7b3e5fc7b8bb8eeb44edd28
  • alt-python27-test_2.7.18-8_amd64.deb
    sha:b46bd2d946bc15eab19b3875b382003c5da69002
  • alt-python27-tkinter_2.7.18-8_amd64.deb
    sha:e8f8f105c4d462a5b1f03bcfb8f63efd17adc95a
  • alt-python27-tools_2.7.18-8_amd64.deb
    sha:7ca60ab6b4495bc74a1294de191e484e6eb78977
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.